AMD "Sinkclose" (CVE-2023-31315) in Framework 13-inch laptop?

AMD has already released the firmware patch for these CPUs. I would be very surprised if Framework doesn’t release an update with that CPU (probably in the next month or two, potentially sooner if you use a beta update).

That page does list specific families of processors, including “AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics”. That is the family of processors that your CPU is in so it is affected.

Directly below that it lists that for those processors the issue was resolved in PhoenixPI-FP8-FP7 version 1.1.0.3.

Currently your laptop’s firmware has PhoenixPI-FP8-FP7 version 1.1.0.2a.

The latest firmware update for the Intel based Framework mainboards patched 8 security vulnerabilities including one Intel CPU vulnerability that was rated 7.2 on the Common Vulnerability Scoring System and a an motherboard firmware vulnerability (which also affected motherboards from other brands such as Lenovo) rated a 9.8. By comparison this AMD issue is rated a 7.5.

New security vulnerabilities get discovered all the time and then get fixed through a firmware update. Buying a new motherboard+CPU just to get away from a security vulnerability that AMD has already released a fix for (and Framework should hopefully be releasing soon) does not help avoid security vulnerabilites.

If you do plan on switching mainboards to avoid these issues then you should probably plan on switching every couple weeks as new vulnerabilities get discovered and one ones get patched (which motherboard has fewer severe security issues at any given time varies).

2 Likes